First published: Mon Jun 28 2010(Updated: )
Multiple stack-based buffer overflows in the jclient._Java_novell_jclient_JClient_defineClass@20 function in jclient.dll in the Tomcat web server in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allow remote authenticated users to execute arbitrary code via the (1) EnteredClassID or (2) NewClassName parameter to nps/servlet/webacc.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell iManager | =2.7.3-ftf2 | |
Novell iManager | =2.7.3 | |
Novell iManager | =2.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1929 is considered to have a high severity rating due to its potential for remote code execution by authenticated users.
To fix CVE-2010-1929, update Novell iManager to version 2.7.3 FTF3 or later, which includes patches for the vulnerability.
CVE-2010-1929 affects Novell iManager versions 2.7.0, 2.7.3, and 2.7.3 FTF2.
No, CVE-2010-1929 requires remote authenticated access for exploitation.
CVE-2010-1929 is a stack-based buffer overflow vulnerability.